Bidirectional Access Visualization for Enterprise Network Permissions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access permissions management systems lack effective bi-directional visualization and monitoring of user authority over network objects in enterprise-wide networks, particularly for containers that include or exclude data elements, leading to inefficiencies in managing and reporting access rights.

Innovation Solution

A system and method for providing bi-directional visualization and monitoring of user authority over SACs (containers) in an enterprise-wide network, including user-wise and SAC-wise visualization, monitoring, and reporting, which enables IT administrators to manage and revoke access permissions efficiently, while distinguishing between network objects and data elements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If traditional access permissions management systems are used, then basic access control is maintained, but bi-directional visualization and monitoring of user authority over network objects is ineffective

Engineering Contradiction:
Improvevisualization of user authorityVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system segments the visualization of user authority into two distinct bidirectional views: user-wise visualization (showing which SACs a user has authority over) and SAC-wise visualization (showing which users have authority over a given SAC). This segmentation allows comprehensive monitoring to be achieved through structured, manageable perspectives rather than a single complex overview.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a bidirectional dimension to traditional unidirectional access control visualization. By adding the reverse perspective (SAC-wise view complementing the user-wise view), the system creates a two-dimensional visualization framework that captures complete authority relationships without requiring excessive system complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If comprehensive monitoring of user authority is implemented, then access control security is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control securityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The monitoring system is designed to serve multiple functions through a unified architecture: it provides user-wise visualization, SAC-wise visualization, and monitoring of authority exercise all through the same system framework. This multi-functionality reduces overall system complexity by avoiding redundant separate monitoring mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements feedback mechanisms that monitor the exercise of authority by users over SACs and provide SAC-wise reporting. This feedback loop enables security improvements by detecting and reporting actual authority usage patterns, allowing administrators to respond to security concerns based on real data rather than theoretical risk assessments.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If differentiation between network objects and data elements is made, then access management precision is improved, but system complexity increases

Engineering Contradiction:
Improveaccess management precisionVSAvoidclassification system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system applies local quality differentiation by treating network objects (SACs) and data elements with distinct access control characteristics. The bidirectional visualization system displays authority relationships differently for each type, providing precise access management tailored to the specific nature of each object while maintaining a unified system architecture.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11496476B2Access permissions management system and method
Publication Date: 2022.11.08 VARONIS SYSTEMS INC
  • US11496476B2 patent drawing
  • US11496476B2 patent drawing
  • US11496476B2 patent drawing

AI summary

A system for providing bi-directional visualization of authority of users over SACs in an enterprise-wide network, the system including functionality for providing user-wise visualization of the authority of a given user over at least one SAC in respect of which the user has authority, and functionality for providing SAC-wise visualization for a given SAC of the authority of at least one user over the given SAC.